{"title":"Risk Assessment Method for Balancing Safety, Security, and Privacy in Medical IoT Systems with Remote Maintenance Function","authors":"R. Sasaki","doi":"10.1109/QRS-C51114.2020.00040","DOIUrl":null,"url":null,"abstract":"It is necessary to evaluate the risk of Internet of Things (IoT) systems not only in terms of security and privacy but also in terms of safety. In addition, because IoT systems are distributed over a wide area, the risk evaluation should consider remote maintenance. Therefore, it is necessary to conduct risk assessment based on the maintainability, safety, security, and privacy (MSSP) concept to realize these four indices in a well-balanced manner. To this end, we proposed an enhanced method that has the function not only to clarify the magnitude of the risk before the measure but also to find an optimal combination of measure plan. As a result of applying this method and the support program named PMSSP to an under-the-sheet type medical IoT monitoring system for multiple vital signs, and we were able to specifically determine the optimal combination of measures.","PeriodicalId":358174,"journal":{"name":"2020 IEEE 20th International Conference on Software Quality, Reliability and Security Companion (QRS-C)","volume":"61 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2020-12-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2020 IEEE 20th International Conference on Software Quality, Reliability and Security Companion (QRS-C)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/QRS-C51114.2020.00040","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2
Abstract
It is necessary to evaluate the risk of Internet of Things (IoT) systems not only in terms of security and privacy but also in terms of safety. In addition, because IoT systems are distributed over a wide area, the risk evaluation should consider remote maintenance. Therefore, it is necessary to conduct risk assessment based on the maintainability, safety, security, and privacy (MSSP) concept to realize these four indices in a well-balanced manner. To this end, we proposed an enhanced method that has the function not only to clarify the magnitude of the risk before the measure but also to find an optimal combination of measure plan. As a result of applying this method and the support program named PMSSP to an under-the-sheet type medical IoT monitoring system for multiple vital signs, and we were able to specifically determine the optimal combination of measures.